Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Federal Agencies

You are the federal customer authorizing and consuming a certified cloud service. Your requirements are about selection, use, and oversight of certified services — and notably, none of them carry a deadline. Binding is not owing a clock: your obligations are standing duties, not timed ones.

Requirements binding you
24
of 246 across the whole ruleset
Deadlines yours
0
binding is not owing a clock
Documents
3
of 17 FRR documents mention you

Force of your requirements

Requirement-level force only — per-class overrides are not tallied here.

MUST · 11MUST NOT · 2SHOULD · 10SHOULD NOT · 1

Your deadlines (0)

Zero of the 68 deadlines in the ruleset name Federal Agencies. This is a real absence, not missing data — your 24 requirements are standing duties without a clock attached.

Full context for each deadline lives in the Obligation Clock, pre-filtered to Agencies.

Your requirements, by document

AGU Agency Use of FedRAMP Certified Cloud Services20
  • AGU-AGC-AIPAgency Internal PoliciesMUST

    Agencies MUST maintain agency-wide policy that aligns with the requirements in OMB Memorandum M-24-15.

  • AGU-AGC-GRCGovernance, Risk, and Compliance ToolsMUST

    Agencies MUST ensure that internal governance, risk, compliance, and inventory tools can produce and ingest machine-readable artifacts using formats identified by FedRAMP, including at least:

  • AGU-AGC-LIAAgency Liaison ProgramSHOULD

    Agencies SHOULD assign at least 1 federal employee to be an active participant in the FedRAMP Agency Liaison program.

  • AGU-AGC-NAANotify FedRAMP After AuthorizationMUST

    Agencies MUST notify FedRAMP upon authorizing the use of a cloud service within the scope of FedRAMP, supplying at least the following information:

  • AGU-AGC-NAINotify Additional Information RequestsMUST

    Agencies MUST notify FedRAMP after requesting any additional information or materials from a FedRAMP Certified cloud service offering beyond those required by FedRAMP.

  • AGU-AGC-NARNo Additional Security RequirementsMUST NOT

    Agencies MUST NOT require additional information or materials from FedRAMP Certified cloud service offerings beyond those required by FedRAMP UNLESS the head of the agency or an authorized delegate determines there is a demonstrable need and notifies FedRAMP; this does not apply to seeking clarification or asking general questions about FedRAMP Certification Data.

  • AGU-AGC-SINShared FedRAMP InboxSHOULD

    Agencies SHOULD establish and maintain a dedicated shared FedRAMP agency inbox to serve as the official point of contact for communications between FedRAMP and the agency.

  • AGU-AGC-TPPNo Certification Type or Path PreferencesMUST NOT

    Agencies MUST NOT require cloud service offerings to obtain or maintain a specific FedRAMP Certification Type or FedRAMP Certification Path, UNLESS the head of the agency or an authorized delegate determines there is a demonstrable need and notifies FedRAMP.

  • AGU-AGC-WKGFedRAMP Working GroupsSHOULD

    Agencies SHOULD participate in FedRAMP working groups, communities of practice, and stakeholder engagements to supply feedback and align practices across government.

  • AGU-SPN-MRCMost Recent Consolidated RulesMUST

    Agencies MUST follow the most recent FedRAMP Consolidated Rules when initiating agency-sponsored FedRAMP Certification.

  • AGU-USE-ABUAuthorization Before UseMUST

    Agencies MUST complete the Authorization to Operate process for federal information systems that use FedRAMP Certified cloud service offerings.

  • AGU-USE-AFRAccept FedRAMP RulesMUST

    Agencies MUST allow FedRAMP Certified cloud service offerings to follow FedRAMP rules.

  • AGU-USE-CLAUsing FedRAMP Class A CertificationsSHOULD NOT

    Agencies SHOULD NOT authorize the use of a FedRAMP Class A Certified cloud service offering for more than 12 months UNLESS the cloud service offering is actively seeking a FedRAMP Class B, C, or D Certification.

  • AGU-USE-DSODesignate Senior OfficialSHOULD

    Agencies SHOULD designate a federal senior information security official to review Ongoing Certification Reports and represent the agency at Quarterly Reviews for cloud service offerings included in agency information systems.

  • AGU-USE-NFCNotify FedRAMP of Monitoring ConcernsMUST

    Agencies MUST notify FedRAMP if information presented in an Ongoing Certification Report, Quarterly Review, or other FedRAMP Certification Data causes significant concerns for the authorizing official that would likely result in rescission of their Authorization to Operate.

  • AGU-USE-NPCNotify Provider of ConcernsSHOULD

    Agencies SHOULD formally notify the cloud service provider if information presented in an Ongoing Certification Report, Quarterly Review, or other FedRAMP Certification Data causes significant concerns for the authorizing official that would likely result in rescission of their Authorization to Operate.

  • AGU-USE-RCFResolve Certification Package ConflictsMUST

    Agencies MUST collaborate with FedRAMP when discrepancies or conflicts arise between agency-specific security determinations and the FedRAMP Certification Package.

  • AGU-USE-RIRReview All Information ResourcesSHOULD

    Agencies SHOULD consider third-party information resources used by the cloud service offering during initial and ongoing authorization activities.

  • AGU-USE-RORReview Ongoing Certification ReportsSHOULD

    Agencies SHOULD review each Ongoing Certification Report to understand how changes to the cloud service offering may impact the risk tolerance documented in the agency Authorization to Operate for the federal information system that includes the cloud service offering in its boundary.

  • AGU-USE-RSGReview Secure Configuration GuidesMUST

    Agencies MUST review the Secure Configuration Guides supplied by Providers and configure relevant security settings.

CCM Collaborative Continuous Monitoring2
  • CCM-AGM-CSCConsider Security CategorySHOULD

    Agencies SHOULD consider the Security Category noted in their Authorization to Operate of the federal information system that includes the cloud service offering in its boundary and assign appropriate information security resources for reviewing Ongoing Certification Reports, attending Quarterly Reviews, and other ongoing FedRAMP Certification Data.

  • CCM-AGM-RORReview Ongoing ReportsMUST

    Agencies MUST review each Ongoing Certification Report to understand how changes to the cloud service offering may impact the previously agreed-upon risk tolerance documented in the agency's Authorization to Operate of a federal information system that includes the cloud service offering in its boundary.

VER Vulnerability Evaluation and Reporting2
  • VER-AGM-MAPMaintain Agency Plans of Action and MilestonesSHOULD

    Agencies SHOULD use vulnerability information reported by the Provider to maintain Plans of Action and Milestones for agency security programs when relevant according to agency security policies (such as if the agency takes action to mitigate the risk of exploitation or authorized the continued use of a cloud service with accepted vulnerabilities that put agency information systems at risk).

  • VER-AGM-RVRReview Vulnerability ReportsSHOULD

    Agencies SHOULD review the information provided in vulnerability reports at appropriate and reasonable intervals commensurate with the expectations and risk posture indicated by their Authorization to Operate, and SHOULD use automated processing and filtering of machine readable information from cloud service providers.